Skip to content

Conversation

@mjnitz02
Copy link
Contributor

@mjnitz02 mjnitz02 commented Oct 24, 2025

This repository is public. Do not put here any private DataRobot or customer's data: code, datasets, model artifacts, .etc.

Summary

Previous format seems to be incompatible with drum installer. We don't actually use this really, but we need it just for records

ptyprocess==0.7.0 ; os_name != 'nt' or (sys_platform != 'emscripten' and sys_platform != 'win32')
pure-eval==0.2.3
py-rust-stemmers==0.1.5
protobuf==5.29.4
Copy link

@semgrep-code-datarobot semgrep-code-datarobot bot Oct 24, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Affected versions of protobuf are vulnerable to Uncontrolled Recursion. The pure-Python implementation of Protocol Buffers is vulnerable to a denial-of-service attack when processing untrusted data with deeply nested or recursive groups/messages, potentially causing the Python recursion limit to be exceeded.

Manual Review Advice: A vulnerability from this advisory is reachable if you have setup the Protobuf pure-Python backend (the other backends are safe)

Fix: Upgrade this library to at least version 5.29.5 at datarobot-user-models/public_dropin_environments/python311_genai_agents/requirements.txt:83.

Reference(s): GHSA-8qvm-5x2c-j2w7, CVE-2025-4565

🍰 Fixed in commit 6d30203 🍰

@mjnitz02 mjnitz02 changed the title [BUZZOK-28206] Fix broken requirements.txt in GenAI Agents environment [BUZZOK-28206] Fix broken requirements.txt in GenAI Agents environment (Need to remove all ; things in requirements.txt) Oct 24, 2025
@engprod-2
Copy link

engprod-2 bot commented Oct 24, 2025

The Needs Review labels were added based on the following file changes.

Team @datarobot/buzok (#genai) was assigned because of changes in files:

public_dropin_environments/python311_genai_agents/env_info.json
public_dropin_environments/python311_genai_agents/requirements.txt

If you think that there are some issues with ownership, please discuss with C&A domain at #sdtk slack channel and create PR to update DRCODEOWNERS\CODEOWNERS file.

Copy link
Contributor

@jpclemens0 jpclemens0 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Duplicated packages

nvidia-nat-crewai==1.3.0rc3 ; python_full_version >= '3.11'
nvidia-nat-langchain==1.3.0rc3 ; python_full_version >= '3.11'
nvidia-nat-opentelemetry==1.3.0rc3 ; python_full_version >= '3.11'
numpy==1.26.4
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two numpy?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmmm... Yea, maybe this is a problem. The requirements.txt here is technically fake and it only exists in a python 3.11 image. The issue is that its hard to create a drum compatible requirements.txt from a uv.lock file. The two things don't really co-exist very easily together.

nvidia-nat-opentelemetry==1.3.0rc3 ; python_full_version >= '3.11'
numpy==1.26.4
numpy==2.3.4
nvidia-nat==1.3.0rc3
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nat requires python >= 3.11

s3transfer==0.13.1
scipy==1.15.3 ; python_full_version < '3.11'
scipy==1.16.2 ; python_full_version >= '3.11'
scipy==1.15.3
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two scipy?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants